CVE-2026-91016: Schwachstellen-Eintrag (NVD)
The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-16 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-91016 | Motors Plugin up to 1.4.120 on WordPress user id authorization (EUVD-2026-81357)
A vulnerability identified as problematic has been detected in Motors Plugin up to 1.4.120 on WordPress. This affects an unknown part. The manipulation of the argument user id leads to authorization bypass. This vulnerability is documented